CVE-2020-0618

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

8.8
CVSS 3.1
99.0 %
EPSS (current)
2024-09-18
KEV addition
Yes
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Microsoft / SQL Server

Published: 2020-02-11 · Due (CISA): 2024-10-09

CWE: CWE-502 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2020/CVE-2020-0618.yamlMicrosoft SQL Server Reporting Services - Remote Code Execution–
metasploitexploit/windows/http/ssrs_navcorrector_viewstateexploit/windows/http/ssrs_navcorrector_viewstate2020-02-11
exploitdb48816Microsoft SQL Server Reporting Services 2016 - Remote Code Execution2020-09-17

References only — no downloads or instructions.

Sources